|
(11) | EP 2 293 515 B1 |
| (12) | EUROPEAN PATENT SPECIFICATION |
|
|
| (54) |
Method, network element, and mobile station for negotiating encryption algorithms Verfahren, Netzwerkelement und mobile Station zur Übermittlung von Verschlüsselungsalgorithmen Procédé, élément de réseau et station mobile pour négocier des algorithmes de cryptage |
|
|
|||||||||||||||||||||||||||||||
| Note: Within nine months from the publication of the mention of the grant of the European patent, any person may give notice to the European Patent Office of opposition to the European patent granted. Notice of opposition shall be filed in a written reasoned statement. It shall not be deemed to have been filed until the opposition fee has been paid. (Art. 99(1) European Patent Convention). |
Field of the Invention
Background of the Invention
Summary of the Invention
obtaining information that a plug-in card of an MS does not support a A5/4encryption algorithm according to the security context information of the MS;
deleting the A5/4 encryption algorithm from an encryption algorithm list permitted by a core network element according to the information that the plug-in card of the MS does not support the A5/4 encryption algorithm; and
sending the encryption algorithm list excluding the A5/4 encryption algorithm to an access network element, so that the access network element selects an encryption algorithm according to the encryption algorithm list excluding the A5/4 encryption algorithm and MS capability information sent from the MS and sends the selected encryption algorithm to the MS;
wherein:
the obtaining the information that the plug-in card of the MS does not support the A5/4 encryption algorithm according to the security context information of the MS comprises:
if an authentication vector in the security context information of the MS is an authentication triplet, acquiring that the type of the plug-in card of the MS is a subscriber identity module, SIM, card, and further acquiring that the plug-in card of the MS does not support the A5/4 encryption algorithm; or
if a key part of the authentication vector of the MS includes a 64-bit encryption key, acquiring that the plug-in card of the MS does not support the A5/4 encryption algorithm.
an obtaining unit, configured to obtain information that a plug-in card of an MS is a subscriber identity module, SIM, card that does not support a A5/4 encryption algorithm, according to security context information of the MS;
an algorithm deleting unit, configured to delete the A5/4 encryption algorithm from an encryption algorithm list permitted by the core network element according to the information obtained by the obtaining unit that the plug-in card of the MS does not support the A5/4 encryption algorithm; and
a sending unit, configured to send the encryption algorithm list excluding the A5/4 encryption algorithm processed by the algorithm deleting unit to an access network element, so that the access network element selects an encryption algorithm according to the encryption algorithm list excluding the A5/4 encryption algorithm and MS capability information sent from the MS and sends the selected encryption algorithm to the MS;
wherein:
the obtaining unit is configured to obtain information that the plug-in card of the MS is a subscriber identity module, SIM, card that does not support the A5/4 encryption algorithm, according to that an authentication vector in the security context information of the MS is an authentication triplet or a key part of the authentication vector of the MS comprises a 64-bit encryption key.
Brief Description of the Drawings
FIG. 1 is a flowchart on a core network element in a first embodiment of an inventive method for negotiating encryption algorithms;
FIG. 2 shows an authentication process;
FIG. 3 illustrates a signaling interaction process in a second embodiment of the method for negotiating encryption algorithms;
FIG. 4 illustrates a signaling interaction process in a third embodiment of the method for negotiating encryption algorithms;
FIG. 5 illustrates a signaling interaction process in a fourth embodiment of the method for negotiating encryption algorithms;
FIG. 6 illustrates a signaling interaction process in a sixth embodiment of the method for negotiating encryption algorithms;
FIG. 7 shows a structure of a core network element in an embodiment of the present invention;
FIG. 8 shows a structure of an access network element in an embodiment of the present invention; and
FIG. 9 shows a structure of an MS in an embodiment of the present invention.
Detailed Description of the Embodiments
Step 101: Obtain the information that the plug-in card of the MS does not support
the first encryption algorithm.
The first encryption algorithm is an encryption algorithm that is not supported by
the plug-in card of the MS but is supported by the core network element.
Step 102: Delete the first encryption algorithm from an encryption algorithm list permitted by the core network element according to the information that the plug-in card of the MS does not support the first encryption algorithm.
Step 103: Send the encryption algorithm list permitted by the core network element to the access network element, so that the access network element selects an encryption algorithm according to the encryption algorithm list permitted by the core network element and the MS capability information sent from the MS and sends the selected encryption algorithm to the MS.
Step 201: If the MSC does not store the authentication triplet of the MS, the MSC sends a Send Authentication Info message that carries the international mobile subscriber identity (IMSI) of the MS to the home location register (HLR).
Step 202: The HLR searches for the authentication triplet of the MS according to the IMSI of the MS, and sends a Send Authentication Info ACK that carries the found authentication triplet. The authentication triplet includes a random number (RAND), an encryption key (Kc), and a signed response (SERS), and is provided by the AUC. The AUC generates a RAND randomly, and processes the RAND and the unique authentication value Ki of the MS by using the A3 algorithm. Then, the AUC obtains the SERS of the network.
Step 203: The MSC sends an Authentication Request that carries a RAND to the MS.
Step 204: The MS processes the RAND and the unique authentication value Ki stored on the MS by using the A3 algorithm, and obtains the SERS of the MS. The MS sends an Authentication Response that carries the SERS of the MS to the MSC.
Step 301: When the periodic location updating timer expires or the MS roams across location areas, the MS initiates a location updating process. The MS initiates an RR connection establishment process. In this process, the MS sends the MS capability information to the BSC. The MS capability information includes the information indicating that the MS supports the encryption algorithm. If the MS supports the A5/4 encryption algorithm in this embodiment, the MS capability information includes the information indicating that the MS supports the A5/4 encryption algorithm. Generally, the MS and the plug-in card configured on the MS implement communications together. The fact that the MS supports the A5/4 encryption algorithm does not mean that the plug-in card of the MS also supports the A5/4 encryption algorithm.
Step 302: After the RR connection is established, the MS sends a Location Updating Request to the MSC/visitor location register (VLR) to indicate the current location information of the MS to the network.
Step 303: The MSC/VLR determines that the MS needs to be authenticated. If the MSC/VLR does not have the authentication vector of the MS, the MSC/VLR may send a Send Authentication Information message that carries the IMSI of the MS to the HLR to which the MS belongs.
Step 304: The HLR searches for the authentication vector of the MS according to the IMSI of the MS. The HLR sends a Send Authentication Info ACK that carries the authentication vector of the MS to the MSC. Because the type of the plug-in card of the MS is a SIM card, the authentication vector returned by the HLR is an authentication triplet. If the type of the plug-in card of the MS is a USIM card, the authentication vector returned by the HLR is an authentication quintuplet. The authentication quintuplet includes a RAND, an expected signed response (XRES), an authentication token (AUTN), an encryption key (CK), and an integrity key (IK). The authentication vector is a kind of security information context of the MS.
Step 305: The MSC/VLR receives an authentication triplet from the HLR, and initiates an authentication process to the MS.
Step 306: After the authentication succeeds, the MSC/VLR and the access network negotiate the encryption algorithms. The MSC/VLR judges the type of the plug-in card of the MS according to the security context information of the MS sent from the HLR. In this embodiment, the security context information of the MS is an authentication triplet. Because the HLR returns the authentication triplet, the plug-in card of the MS is a SIM card. Or the MSC/VLR judges whether the encryption key of the MS in the security context information sent from the HLR includes only a 64-bit encryption key. If the encryption key of the MS includes only the 64-bit encryption key, the MSC/VLR may obtain the information that the plug-in card of the MS does not support the A5/4 encryption algorithm. Because the A5/4 encryption algorithm requires a 128-bit encryption key, the MSC/VLR executes step 307. Otherwise, the MSC/VLR executes the process of negotiating encryption algorithms in the prior art, that is, it does not execute step 307 to step 313. For example, if the encryption key includes a CK or an IK, the MSC/VLR may determine that the encryption key is a 128-bit encryption key, and perform the encryption algorithms negotiation process related to the USIM card.
Step 307: The MSC/VLR deletes the A5/4 encryption algorithm from the encryption algorithm list permitted by the MSC/VLR. The MSC/VLR sends a cipher mode command to the BSC, where the cipher mode command carries a 64-bit encryption key Kc and the encryption algorithm list permitted by the MSC/VLR. The encryption algorithm list sent from the MSC/VLR does not include the A5/4 encryption algorithm. In the cipher mode command, the bitmap may be used to represent the encryption algorithm list permitted by the network. For example, because the A5/4 encryption algorithm is deleted, the bit corresponding to the A5/4 encryption algorithm is set to 0, indicating that the A5/4 encryption algorithm is forbidden.
Step 308: The BSC selects an encryption algorithm according to the encryption algorithm list sent from the MSC/VLR and the MS capability information sent from the MS, and sends an encryption command to the base transceiver station (BTS), where the encryption command carries the selected encryption algorithm, the encryption key Kc, and the cipher mode command. Because the encryption algorithm list sent from the MSC/VLR does not include the A5/4 encryption algorithm, the BSC does not select the A5/4 algorithm even if the MS capability information indicates that the MS supports the A5/4 algorithm.
Step 309: The BTS forwards the cipher mode command to the MS, and activates the data decryption function in the upstream direction.
Step 310: After the MS receives the cipher mode command, the MS starts the data transmission and receiving in cipher mode. After performing the actions according to the cipher mode command, the MS sends a Cipher Mode Complete message to the BTS.
Step 311: After receiving the Cipher Mode Complete message, the BTS starts its own encryption process. The BTS forwards the Cipher Mode Complete message to the BSC through a data indication. The data indication is an Abis message transmitted between the BSC and the BTS. The interface between the BSC and the BTS is an Abis interface.
Step 312: The BSC sends a Cipher Mode Complete message to the MSC, indicating that the cipher mode is completed. The Cipher Mode Complete message carries the encryption algorithm selected by the BSC. After the encryption process is completed, the MS may collaborate with the BTS in sending and receiving the encryption data on radio links.
Step 313: After receiving the Cipher Mode Complete message, the MSC/VLR sends a Location Updating Accept message to the MS, indicating that the location updating request of the MS is completed. The MS location information on the network is already updated to the current location information of the MS.
Step 401: Receive an encryption key sent from the core network element.
Step 402: If the encryption key does not match the first encryption algorithm, select an encryption algorithm from encryption algorithms other than the first encryption algorithm, and send the selected encryption algorithm to the MS.
Step 501 to step 505 are similar to step 301 to step 305, and are not further described.
Step 506: After the authentication succeeds, the MSC/VLR negotiates encryption algorithms with the access network. The MSC/VLR sends a cipher mode command to the BSC, where the cipher mode command carries a 64-bit encryption key Kc and an encryption algorithm list permitted by the MSC/VLR. In this embodiment, the MSC does not delete the A5/4 encryption algorithm. Thus, the encryption algorithm list sent from the MSC includes the A5/4 encryption algorithm.
Step 507: The BSC selects an encryption algorithm according to the encryption algorithm supported by the BSC, the MS capability information, the encryption algorithm list sent from the MSCNLR, and the encryption key. Because the encryption key is a 64-bit encryption key, the BSC may not select the A5/4 encryption algorithm even if the MS capability information indicates that the MS supports the A5/4 encryption algorithm and the encryption algorithm list sent from the MSC/VLR includes the A5/4 encryption algorithm. The BSC needs to select an encryption algorithm from encryption algorithms other than the A5/4 encryption algorithm.
Step 508: The BSC sends an encryption command to the BTS, where the encryption command carries the selected encryption algorithm, the encryption key Kc, and the cipher mode command.
Step 509 to step 513 are similar to step 309 to step 313, and are not further described.
if the type of the plug-in card of the MS is a SIM card, the MS sends the MS capability information indicating that the MS does not support the first encryption algorithm to the access network element, so that the access network element selects an encryption algorithm from encryption algorithms other than the first encryption algorithm according to the encryption algorithm list sent from the core network element and the MS capability information sent from the MS and sends the selected encryption algorithm to the MS;
or if the type of the plug-in card of the MS is a SIM card, the MS deletes the first encryption algorithm from the encryption algorithm list supported by the MS, and sends the encryption algorithm list excluding the first encryption algorithm to the access network element, so that the access network element selects an encryption algorithm from encryption algorithms other than the first encryption algorithm according to the encryption algorithm list sent from the core network element and the encryption algorithm list sent from the MS and sends the selected encryption algorithm to the MS.
Step 701: The MS judges the type of the plug-in card of the MS. If the type of the
plug-in card is a SIM card, the MS sends the MS capability information indicating
that the MS does not support the A5/4 encryption algorithm to the BSC. If the type
of the plug-in card of the MS is a USIM card, the MS may send the MS capability information
indicating that the MS supports the A5/4 encryption algorithm to the BSC. The MS sends
the MS capability information in the process of RR connection establishment. The MS
capability information indicating that the MS supports the A5/4 encryption algorithm
may be represented in the form of a bitmap. For example, if the MS capability information
indicates that the MS supports the A5/4 encryption algorithm, the bit corresponding
to the A5/4 encryption algorithm is set to 1; if the MS capability information indicates
that the MS does not support the A5/4 encryption algorithm, the bit corresponding
to the A5/4 encryption algorithm is set to 0.
Or in step 701, the MS may delete the A5/4 algorithm from the encryption algorithm
list supported by the MS, and send the encryption algorithm list excluding the A5/4
encryption algorithm to the BSC.
Step 702 to step 705 are the same as step 302 to step 305.
Step 706: After the authentication succeeds, the MSC/VLR negotiates encryption algorithms with the access network. The MSC/VLR sends a cipher mode command to the BSC, where the cipher mode command carries a 64-bit encryption key Kc and the encryption algorithm list permitted by the MSC/VLR. In this embodiment, the encryption algorithm list sent from the MSC/VLR includes the A5/4 encryption algorithm.
Step 707: The BSC selects an encryption algorithm according to the encryption algorithms supported by the BSC, MS capability information, the encryption algorithm list sent from the MSC/VLR, and the encryption key, and sends an encryption command to the BTS, where the encryption command carries the selected encryption algorithm, the encryption key Kc, and the cipher mode command. Because the MS capability information indicates that the MS does not support the A5/4 encryption algorithm or the encryption algorithm list supported by the MS does not include the A5/4 encryption algorithm, the BSC may not select the A5/4 encryption algorithm, but select an encryption algorithm from encryption algorithms other than the A5/4 encryption algorithm.
Step 708 to step 712 are similar to step 309 to step 313, and are not further described.
obtaining (101) information that a plug-in card of a mobile station, MS, does not support a A5/4 encryption algorithm according to the security context information of the MS;
deleting (102) the A5/4 encryption algorithm from an encryption algorithm list permitted by a core network element according to the information that the plug-in card of the MS does not support the A5/4 encryption algorithm; and
sending (103) the encryption algorithm list excluding the A5/4 encryption algorithm to an access network element, so that the access network element selects an encryption algorithm according to the encryption algorithm list excluding the A5/4 encryption algorithm and MS capability information sent from the MS and sends the selected encryption algorithm to the MS;
wherein:
the obtaining the information that the plug-in card of the MS does not support the A5/4 encryption algorithm according to the security context information of the MS comprises:
if an authentication vector in the security context information of the MS is an authentication triplet, acquiring that the type of the plug-in card of the MS is a subscriber identity module, SIM, card, and further acquiring that the plug-in card of the MS does not support the A5/4 encryption algorithm; or
if a key part of the authentication vector of the MS includes a 64-bit encryption key, acquiring that the plug-in card of the MS does not support the A5/4 encryption algorithm.
an obtaining unit (11), configured to obtain information that a plug-in card of a mobile station, MS, is a subscriber identity module, SIM, card that does not support a A5/4 encryption algorithm, according to security context information of the MS ;
an algorithm deleting unit (12), configured to delete the A5/4 encryption algorithm from an encryption algorithm list permitted by a core network element according to the information obtained by the obtaining unit that the plug-in card of the MS does not support the A5/4 encryption algorithm; and
a sending unit (13), configured to send the encryption algorithm list excluding the A5/4 encryption algorithm processed by the algorithm deleting unit to an access network element, so that the access network element selects an encryption algorithm according to the encryption algorithm list excluding the A5/4 encryption algorithm and MS capability information sent from the MS, and sends the selected encryption algorithm to the MS;
wherein:
the obtaining unit is configured to obtain information that the plug-in card of the MS is a subscriber identity module, SIM, card that does not support the A5/4 encryption algorithm, according to that an authentication vector in the security context information of the MS is an authentication triplet or a key part of the authentication vector of the MS comprises a 64-bit encryption key.
the core network element is a mobile switch center, MSC, or a visitors location register, VLR.
Erhalten (101) von Informationen, dass eine Einsteckkarte einer Mobilstation, MS, einen A5/4-Verschlüsselungsalgorithmus nicht unterstützt, gemäß den Sicherheitskontextinformationen der MS;
Löschen (102) des AS/4-Verschlüsselungsalgorithmus aus einer von einem Kernnetzelement gestatteten Verschlüsselungsalgorithmusliste gemäß den Informationen, dass die Einsteckkarte der MS den A5/4-Verschlüsselungsalgorithmus nicht unterstützt; und
Senden (103) der Verschlüsselungsalgorithmusliste ohne den A5/4-Verschlüsselungsalgorithmus zu einem Zugangsnetzelement, so dass das Zugangsnetzelement gemäß der Verschlüsselungsalgorithmusliste ohne den A5/4-Verschlüsselungsalgorithmus und von der MS gesendeten MS-Fähigkeitsinformationen einen Verschlüsselungsalgorithmus auswählt und den ausgewählten Verschlüsselungsalgorithmus zu der MS sendet;
wobei
das Erhalten der Informationen, dass die Einsteckkarte der MS den A5/4-Verschlüsselungsalgorithmus nicht unterstützt, gemäß den SicherheitskontextInformationen der MS Folgendes umfasst:
wenn ein Authentifizierungsvektor in den Sicherheitskontextinformationen der MS ein Authentifizierungstripel ist, Erfassen, dass die Art der Einsteckkarte der MS eine Teilnehmeridentitätsmodul- bzw. SIM-Karte ist, und ferner Erfassen, dass die Einsteckkarte der MS den AS/4-Verschlüsselungsalgorithmus nicht unterstützt; oder wenn ein Schlüsselteil des Authentifizierungsvektors der MS einen 64-Bit-Verschlüsselungsschlüssel umfasst, Erfassen, dass die Einsteckkarte der MS den AS/4-Verschlüsselungsalgorithmus nicht unterstützt.
eine Erhalteeinheit (11), ausgelegt zum Erhalten von Informationen, dass eine Einsteckkarte einer Mobilstation, MS, eine Teilnehmeridentitätsmodul- bzw. SIM-Karte ist, die einen A5/4-Verschlüsselungsalgorithmus nicht unterstützt, gemäß Sicherheitskontextinformationen der MS;
eine Algorithmuslöscheinheit (12), ausgelegt zum Löschen des A5/4-Verschlüsselungsalgorithmus aus einer von einem Kernnetzelement gestatteten Verschlüsselungsalgorithmusliste gemäß den durch die Erhalteeinheit erhaltenen Informationen, dass die Einsteckkarte der MS den A5/4-Verschlüsselungs-algorithmus nicht unterstützt; und
eine Sendeeinheit (13), ausgelegt zum Senden der Verschlüsselungsalgorithmusliste ohne den durch die Algorithmuslöscheinheit verarbeiteten A5/4-Verschlüsselungsalgorithmus zu einem Zugangsnetzelement, so dass das Zugangsnetzelement gemäß der Verschlüsselungsalgorithmusliste ohne den A5/4-Verschlüsselungsalgorithmus und von der MS gesendeten MS-Fähigkeitsinformationen einen Verschlüsselungsalgorithmus auswählt und den ausgewählten Verschlüsselungsalgorithmus zu der MS sendet;
wobei
die Erhalteeinheit dafür ausgelegt ist, Informationen zu erhalten, dass die Einsteckkarte der MS eine Teilnehmeridentitätsmodul- bzw. SIM-Karte ist, die den AS/4-Verschlüsselungsalgorithmus nicht unterstützt, gemäß denen ein Authentifizierungsvektor in den Sicherheitskontextinformationen der MS ein Authentifizierungstripel ist oder ein Schlüsselteil des Authentifizierungsvektors der MS einen 64-Bit-Verschlüsselungsschlüssel umfasst.
obtenir (101) des informations indiquant qu'une carte enfichable d'une station mobile, dite MS, ne prend pas en charge un algorithme de chiffrement A5/4 selon des informations de contexte de sécurité de la MS ; et
supprimer (102) l'algorithme de chiffrement A5/4 d'une liste d'algorithmes de chiffrement admise par un élément de réseau d'infrastructure selon les informations indiquant que la carte enfichable de la MS ne prend pas en charge l'algorithme de chiffrement A5/4 ; et
transmettre (103) la liste d'algorithmes de chiffrement excluant l'algorithme de chiffrement A5/4 à un élément de réseau d'accès pour permettre à l'élément de réseau d'accès de sélectionner un algorithme de chiffrement selon la liste d'algorithmes de chiffrement excluant l'algorithme de chiffrement A5/4 et des informations de fonctionnalité de la MS transmises par la MS, et de transmettre l'algorithme de chiffrement sélectionné à la MS ;
laquelle étape consistant à obtenir les informations indiquant que la carte enfichable de la MS ne prend pas en charge l'algorithme de chiffrement A5/4 selon les informations de contexte de sécurité de la MS comprend l'étape consistant à :
si un vecteur d'authentification dans les informations de contexte de sécurité de la MS est un triplet d'authentification, établir que la carte enfichable de la MS est du type module d'identification d'abonné, dit SIM, et établir en outre que la carte enfichable de la MS ne prend pas en charge l'algorithme de chiffrement A5/4 ; ou
si une partie clé du vecteur d'authentification de la MS comporte une clé de chiffrement sur 64 bits, établir que la carte enfichable de la MS ne prend pas en charge l'algorithme de chiffrement A5/4.
une unité d'obtention (11), conçue pour obtenir des informations indiquant qu'une carte enfichable d'une station mobile, dite MS, est une carte du type module d'identification d'abonné, dit SIM, qui ne prend pas en charge un algorithme de chiffrement A5/4 selon des informations de contexte de sécurité de la MS ;
une unité de suppression d'algorithme (12), conçue pour supprimer l'algorithme de chiffrement A5/4 d'une liste d'algorithmes de chiffrement admise par un élément de réseau d'infrastructure selon les informations obtenues par l'unité d'obtention indiquant que la carte enfichable de la MS ne prend pas en charge l'algorithme de chiffrement A5/4 ; et
une unité de transmission (13), conçue pour transmettre la liste d'algorithmes de chiffrement excluant l'algorithme de chiffrement A5/4 traitée par l'unité de suppression d'algorithme à un élément de réseau d'accès pour permettre à l'élément de réseau d'accès de sélectionner un algorithme de chiffrement selon la liste d'algorithmes de chiffrement excluant l'algorithme de chiffrement A5/4 et des informations de fonctionnalité de la MS transmises par la MS, et de transmettre l'algorithme de chiffrement sélectionné à la MS ;
laquelle unité d'obtention est conçue pour obtenir des informations indiquant que la carte enfichable de la MS est une carte du type module d'identification d'abonné, dit SIM, qui ne prend pas en charge l'algorithme de chiffrement A5/4 selon qu'un vecteur d'authentification dans les informations de contexte de sécurité de la MS est un triplet d'authentification ou qu'une partie clé du vecteur d'authentification de la MS comporte une clé de chiffrement sur 64 bits.
REFERENCES CITED IN THE DESCRIPTION
Patent documents cited in the description
Non-patent literature cited in the description